Framework & Certification Register
| Owner | Classification | Version | Effective | Next review | Status |
|---|---|---|---|---|---|
| Sekhar Prakash | Internal | 0.1 | 2026-08-27 | 2026-11-27 | Draft |
Purpose. Records which compliance frameworks Finaisse maps to its control set, which it certifies, in what sequence, and the applicability of those excluded. Supports customer security-questionnaire responses and audit planning.
Operating principle: map broadly, certify selectively
- Mapping adds one lens (
maps_to) to each control and makes the programme answerable to that framework immediately. - Certification is a scheduled, audited engagement pursued only where the market requires it, in priority order.
- One control set answers every mapped framework → a customer questionnaire becomes a lookup rather than a project.
Certification driver: SOC 1 is required
- Finaisse performs straight-through processing — automated posting of validated journals and invoices to the customer's books under approval rules.
- This places Finaisse within the customer's internal control over financial reporting (ICFR), for which their external auditors require SOC 1 assurance.
Peer benchmark (finance-automation platforms that post to the books):
| Vendor | SOC 1 Type 2 | SOC 2 Type 2 | ISO 27001 | ISO 42001 | Source confidence |
|---|---|---|---|---|---|
| BlackLine | Yes | Yes | Yes (+27017/18/701) | Yes | Primary (vendor + investor sources) |
| Esker | Yes | Reported | Yes | — | Primary (press release; 2012/2014 exams — verify current) |
| FloQast | Reported (secondary) | Yes | Yes (+27701) | Reported (secondary) | SOC 2 / ISO primary; SOC 1 / 42001 unconfirmed |
| HighRadius | Not confirmed | Yes | Yes (27001:2022) | — | ISO / SOC via trust centre; SOC 1 unconfirmed |
- Category baseline: SOC 1 Type 2 · SOC 2 Type 2 · ISO 27001, with ISO 42001 emerging as the AI differentiator.
- Current vendor status should be confirmed from each provider's trust centre before external citation.
Certification track (priority order)
| # | Certification | Attests | Trigger | Sequence | Status |
|---|---|---|---|---|---|
| 1 | SOC 2 Type 2 (incl. Processing Integrity) | Security, availability, confidentiality, processing accuracy | Customer security requirement | Now — primary target | In preparation |
| 2 | SOC 1 Type 2 | Controls over customer financial reporting (ICFR) | Straight-through posting to customer books | After STP live plus 6–12-month observation; combine with SOC 2 | Required, unscheduled |
| 3 | ISO 27001 | Information Security Management System | International / enterprise demand | On demand | Map now, certify on demand |
| 4 | ISO/IEC 42001 | AI management system | AI-native platform differentiation | Early | Map now |
SOC 3 (public summary of SOC 2) is optional and low-effort once SOC 2 is held.
Mapped frameworks (answerability, not certification)
| Framework | Purpose | Notes |
|---|---|---|
| GDPR | EU personal-data lawfulness and data-subject rights | Delivered via DPA; overlaps Domain 2 and SOC 2 |
| DPDP (India) | Primary regulatory regime | Mapped alongside GDPR; selected by customer geography |
| EU AI Act | AI risk and transparency obligations | Paired with ISO 42001 |
| CIS v8 / OWASP | Engineering baselines | Present in the coverage crosswalk |
Designed-in, not yet applicable
- Both are data-type-triggered regimes.
- The majority of each is satisfied by the generic Restricted-data controls (Domains 2, 4, 11), engineered to the union of all data-regime requirements.
- Data-type-specific controls are documented as activation triggers, not implemented ahead of the data.
| Framework | Applicability | Activation trigger and unique requirements |
|---|---|---|
| PCI-DSS | Not applicable | Activates on card PAN acceptance. Keep PAN out of scope via a processor (SAQ A). Additional requirements: cardholder-data-environment scoping and segmentation, no storage of sensitive authentication data, PAN masking, dedicated key management, ASV scans. |
| HIPAA | Not applicable | Activates if a healthcare tenant transmits PHI. Technical safeguards already met by SOC 2 / ISO 27001. Additional requirements: business associate agreement, breach-notification rule, minimum-necessary. No formal HIPAA certification exists; HITRUST is the certifiable proxy. |
Straight-through-processing control objectives (SOC 1)
Design the following into the STP implementation from the outset. Mapped to Domains 16 (financial-data integrity), 17 (business logic), and 4 (identity and access):
- Approval-rule change management under authorisation and change control.
- Enforcement with no bypass of required approval.
- Completeness and accuracy: each approved item posts once and only once; ingress-to-egress reconciliation.
- Segregation of duties in the approval workflow.
- Immutable audit trail of approver, rule fired, and posting.
- Access control over rule configuration and the posting path.
- Complementary user-entity controls (customer review of configuration; general-ledger reconciliation).
Related
- → Statement of Applicability — the exclusion decisions
- → Control Register — the controls these frameworks map onto
- → Framework Crosswalk — per-framework views
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 0.1 | 2026-08-27 | Sekhar Prakash | Initial register; certification track and applicability decisions. |
Finaisse Internal — Confidential. Not for external distribution.